CVE-2020-0096 is a critical elevation-of-privilege vulnerability in the Android Framework affecting Android 8.0, 8.1, and 9. According to the provided content, the flaw is in startActivities in ActivityStartController.java and arises from a confused deputy condition. Exploitation can allow a local attacker, via a specially crafted file or malicious application flow, to abuse a privileged process and execute arbitrary code or otherwise gain elevated privileges in that privileged context. The issue has been publicly associated with StrandHogg 2.0.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a Proof-of-Concept (PoC) Android application demonstrating the StrandHogg 2 (CVE-2020-0096) vulnerability, which allows local privilege escalation via a confused deputy attack in the Android activity launch system. The repository contains a standard Android project structure, with the main exploit logic implemented in 'MainActivity.java'. This activity programmatically launches a sequence of victim and attacker activities using crafted Intents, exploiting the way Android handles activity launches and task affinities. The attacker activities (Attack1Activity and Attack2Activity) are used to hijack or overlay the victim activities, simulating the attack scenario. The PoC requires the user to modify the target package and class names to match those of the intended victim apps. The repository targets Android versions 8.0, 8.1, and 9, and is intended for research and demonstration purposes. No network endpoints or external IPs are present; the attack is entirely local to the device. The code is written in Java and XML, and the main entry point is 'MainActivity.java'.
This repository is a proof-of-concept (POC) Android application demonstrating exploitation of the StrandHogg 2.0 vulnerability (CVE-2020-0096). The exploit targets Android devices prior to version 10, allowing an attacker to hijack the UI of another app by launching their own activities on top of the target app's activity. The repository is structured as a standard Android Studio project, with the main exploit logic in 'MainActivity.java', which crafts and launches Intents targeting both the attacker's and the victim's activities. The README provides context, references, and usage instructions, indicating that the code must be modified to match the target app's package name and exported activity. No network endpoints or external IPs are present; the attack is local to the device and leverages Android's activity and Intent system. The repository includes build scripts, configuration files, and Android resource files necessary for compiling and running the POC app.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.